{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T14:48:46Z","timestamp":1785250126240,"version":"3.55.0"},"reference-count":48,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T00:00:00Z","timestamp":1650844800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T00:00:00Z","timestamp":1650844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61873160"],"award-info":[{"award-number":["61873160"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61672338"],"award-info":[{"award-number":["61672338"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007219","name":"Natural Science Foundation of Shanghai","doi-asserted-by":"publisher","award":["21ZR1426500"],"award-info":[{"award-number":["21ZR1426500"]}],"id":[{"id":"10.13039\/100007219","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Wireless Com Network"],"published-print":{"date-parts":[[2022,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Network intrusion detection, which takes the extraction and analysis of network traffic features as the main method, plays a vital role in network security protection. The current network traffic feature extraction and analysis for network intrusion detection mostly uses deep learning algorithms. Currently, deep learning requires a lot of training resources and has weak processing capabilities for imbalanced datasets. In this paper, a deep learning model (MFVT) based on feature fusion network and vision transformer architecture is proposed, which improves the processing ability of imbalanced datasets and reduces the sample data resources needed for training. Besides, to improve the traditional raw traffic features extraction methods, a new raw traffic features extraction method (CRP) is proposed, and the CPR uses PCA algorithm to reduce all the processed digital traffic features to the specified dimension. On the IDS 2017 dataset and the IDS 2012 dataset, the ablation experiments show that the performance of the proposed MFVT model is significantly better than other network intrusion detection models, and the detection accuracy can reach the state-of-the-art level. And, when MFVT model is combined with CRP algorithm, the detection accuracy is further improved to 99.99%.<\/jats:p>","DOI":"10.1186\/s13638-022-02103-9","type":"journal-article","created":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T05:02:58Z","timestamp":1650862978000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["MFVT: an anomaly traffic detection method merging feature fusion network and vision transformer architecture"],"prefix":"10.1186","volume":"2022","author":[{"given":"Ming","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8861-5461","authenticated-orcid":false,"given":"Dezhi","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dun","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Han","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chin-Chen","family":"Chang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,4,25]]},"reference":[{"key":"2103_CR1","unstructured":"D. Han, N. Pan, K.-C. Li, A traceable and revocable ciphertext-policy attribute-based encryption scheme based on privacy protection. IEEE Trans. Depend. Secure Comput. (2020)"},{"issue":"5","key":"2103_CR2","doi-asserted-by":"publisher","first-page":"9076","DOI":"10.1109\/JIOT.2019.2927497","volume":"6","author":"M Cui","year":"2019","unstructured":"M. Cui, D. Han, J. Wang, An efficient and safe road condition monitoring authentication scheme based on fog computing. IEEE Internet Things J. 6(5), 9076\u20139084 (2019)","journal-title":"IEEE Internet Things J."},{"issue":"10","key":"2103_CR3","doi-asserted-by":"publisher","first-page":"3162","DOI":"10.1007\/s10489-020-01694-4","volume":"50","author":"Q Tian","year":"2020","unstructured":"Q. Tian, D. Han, K.-C. Li, X. Liu, L. Duan, A. Castiglione, An intrusion detection approach based on improved deep belief network. Appl. Intell. 50(10), 3162\u20133178 (2020)","journal-title":"Appl. Intell."},{"key":"2103_CR4","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","volume":"36","author":"L Hung-Jen","year":"2013","unstructured":"L. Hung-Jen, R.L. Chun-Hung, L. Ying-Chih, T. Kuang-Yuan, Intrusion detection system:a comprehensive review. J. Netw. Comput. Appl. 36, 16\u201324 (2013)","journal-title":"J. Netw. Comput. Appl."},{"key":"2103_CR5","doi-asserted-by":"crossref","unstructured":"D. Li, D. Han, Z. Zheng, T.-H. Weng, H. Li, H. Liu, A. Castiglione, K.-C. Li, Moocschain: A blockchain-based secure storage and sharing scheme for moocs learning. Comput. Stand. Interfaces, 103597 (2021)","DOI":"10.1016\/j.csi.2021.103597"},{"key":"2103_CR6","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/COMST.2014.2336610","volume":"17","author":"DJ Weller-Fahy","year":"2015","unstructured":"D.J. Weller-Fahy, B.J. Borghetti, A.A. Sodemann, A survey of distance and similarity measures used within network intrusion anomaly detection. IEEE Commun. Surv. Tutor. 17, 70\u201391 (2015)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"2103_CR7","first-page":"328","volume":"4","author":"A Abraham","year":"2007","unstructured":"A. Abraham, C. Grosan, C. Martin-Vide, Evolutionary design of intrusion detection programs. Int. J. Netw. Secur. 4, 328\u2013339 (2007)","journal-title":"Int. J. Netw. Secur."},{"key":"2103_CR8","doi-asserted-by":"publisher","first-page":"39","DOI":"10.3390\/a10020039","volume":"10","author":"S Anwar","year":"2017","unstructured":"S. Anwar, J. Mohamad Zain, M. Zolkipli, Z. Inayat, S. Khan, B. Anthony Jnr, V. Chang, From intrusion detection to an intrusion response system: Fundamentals, requirements, and future directions. Algorithms 10, 39 (2017)","journal-title":"Algorithms"},{"key":"2103_CR9","doi-asserted-by":"crossref","unstructured":"W. Zhang, D. Han, K.-C. Li, F.I. Massetto, Wireless sensor network intrusion detection system based on mk-elm. Soft Computing, 1\u201314 (2020)","DOI":"10.1007\/s00500-020-04678-1"},{"key":"2103_CR10","doi-asserted-by":"crossref","unstructured":"W. Liang, L. Xiao, K. Zhang, M. Tang, D. He, K.-C. Li, Data fusion approach for collaborative anomaly intrusion detection in blockchain-based systems. IEEE Internet of Things J. (2021)","DOI":"10.1109\/JIOT.2021.3053842"},{"key":"2103_CR11","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","volume":"60","author":"A Ajith","year":"2016","unstructured":"A. Ajith, G. Crina, M.V. Carlos, A survey of network anomaly detection techniques. J. Netw. Comput. Appl. 60, 19\u201331 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"2103_CR12","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TIFS.2012.2223675","volume":"8","author":"J Zhang","year":"2013","unstructured":"J. Zhang, C. Chao, X. Yang, W. Zhou, X. Yong, Internet traffic classification by aggregating correlated naive bayes predictions. IEEE Trans. Inf. Forens. Secur. 8, 5\u201315 (2013)","journal-title":"IEEE Trans. Inf. Forens. Secur."},{"key":"2103_CR13","doi-asserted-by":"publisher","first-page":"37004","DOI":"10.1109\/ACCESS.2019.2905041","volume":"7","author":"Y Zhang","year":"2019","unstructured":"Y. Zhang, X. Chen, L. Jin, X. Wang, D. Guo, Network intrusion detection: based on deep hierarchical network and original flow data. IEEE Access 7, 37004\u201337016 (2019)","journal-title":"IEEE Access"},{"key":"2103_CR14","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1016\/j.jpdc.2021.02.011","volume":"151","author":"H Liu","year":"2021","unstructured":"H. Liu, D. Han, D. Li, Behavior analysis and blockchain based trust management in vanets. J. Parallel Distrib. Comput. 151, 61\u201369 (2021)","journal-title":"J. Parallel Distrib. Comput."},{"key":"2103_CR15","doi-asserted-by":"crossref","unstructured":"K. Oksuz, B.C. Cam, S. Kalkan, E. Akbas, Imbalance problems in object detection: a review. IEEE Trans. Pattern Anal. Mach. Intell. pp. 1\u20131 (2020)","DOI":"10.1109\/TPAMI.2021.3130188"},{"key":"2103_CR16","unstructured":"A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, N. Houlsby, An image is worth 16x16 words: transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)"},{"key":"2103_CR17","first-page":"108","volume":"1","author":"I Sharafaldin","year":"2018","unstructured":"I. Sharafaldin, A.H. Lashkari, A.A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1, 108\u2013116 (2018)","journal-title":"ICISSp"},{"issue":"3","key":"2103_CR18","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"A. Shiravi, H. Shiravi, M. Tavallaee, A.A. Ghorbani, Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput. Secur. 31(3), 357\u2013374 (2012)","journal-title":"Comput. Secur."},{"key":"2103_CR19","first-page":"52","volume":"51","author":"LI Smith","year":"2002","unstructured":"L.I. Smith, A tutorial on principal components analysis. Inf. Fusion 51, 52 (2002)","journal-title":"Inf. Fusion"},{"key":"2103_CR20","doi-asserted-by":"crossref","unstructured":"D. Han, Y. Zhu, D. Li, W. Liang, A. Souri, K.-C. Li, A blockchain-based auditable access control system for private data in service-centric iot environments. IEEE Trans. Ind. Inform. (2021)","DOI":"10.1109\/TII.2021.3114621"},{"key":"2103_CR21","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1016\/j.ins.2021.08.035","volume":"579","author":"W Liang","year":"2021","unstructured":"W. Liang, Z. Ning, S. Xie, Y. Hu, S. Lu, D. Zhang, Secure fusion approach for the internet of things in smart autonomous multi-robot systems. Inf. Sci. 579, 468\u2013482 (2021)","journal-title":"Inf. Sci."},{"key":"2103_CR22","doi-asserted-by":"crossref","unstructured":"H. Li, D. Han, M. Tang, A privacy-preserving storage scheme for logistics data with assistance of blockchain. IEEE Internet of Things J. (2021)","DOI":"10.1109\/JIOT.2021.3107846"},{"key":"2103_CR23","doi-asserted-by":"crossref","unstructured":"X. Chen, W. Liang, J. Xu, C. Wang, K.-C. Li, M. Qiu, An efficient service recommendation algorithm for cyber-physical-social systems. IEEE Trans. Netw. Sci. Eng. (2021)","DOI":"10.1109\/TNSE.2021.3092204"},{"key":"2103_CR24","unstructured":"J.P. Anderson, Computer security threat monitoring and surveillance (1980)"},{"key":"2103_CR25","doi-asserted-by":"crossref","unstructured":"C.L. Yin, Y.F. Zhu, J.L. Fei, X.Z. He, A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access, pp. 1\u20131 (2017)","DOI":"10.1109\/ACCESS.2017.2762418"},{"key":"2103_CR26","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1016\/j.asoc.2014.01.028","volume":"18","author":"F Kuang","year":"2014","unstructured":"F. Kuang, W. Xu, S. Zhang, A novel hybrid kpca and svm with ga model for intrusion detection. Appl. Soft Comput. 18, 178\u2013184 (2014)","journal-title":"Appl. Soft Comput."},{"key":"2103_CR27","doi-asserted-by":"crossref","unstructured":"R.R. Reddy, Y. Ramadevi, K. Sunitha, Effective discriminant function for intrusion detection using svm. In: 2016 International Conference on Advances in Computing, Communications and Informatics (ICACCI), pp. 1148\u20131153 (2016)","DOI":"10.1109\/ICACCI.2016.7732199"},{"key":"2103_CR28","doi-asserted-by":"crossref","unstructured":"W. Li, P. Yi, Y. Wu, L. Pan, J. Li, A new intrusion detection system based on knn classification algorithm in wireless sensor network. J. Electr. Comput. Eng. 2014 (2014)","DOI":"10.1155\/2014\/240217"},{"key":"2103_CR29","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1016\/j.procs.2016.06.047","volume":"89","author":"N Farnaaz","year":"2016","unstructured":"N. Farnaaz, M.A. Jabbar, Random forest modeling for network intrusion detection system. Procedia Comput. Sci. 89, 213\u2013217 (2016)","journal-title":"Procedia Comput. Sci."},{"key":"2103_CR30","doi-asserted-by":"crossref","unstructured":"Random-forests-based network intrusion detection systems, IEEE Trans. Syst. Man Cybernet. Part C 38, 649\u2013659 (2008)","DOI":"10.1109\/TSMCC.2008.923876"},{"key":"2103_CR31","doi-asserted-by":"crossref","unstructured":"Y. Dhote, S. Agrawal, A.J. Deen, A survey on feature selection techniques for internet traffic classification. In: International Conference on Computational Intelligence & Communication Networks, pp. 1375\u20131380 (2015). IEEE","DOI":"10.1109\/CICN.2015.267"},{"key":"2103_CR32","doi-asserted-by":"publisher","first-page":"1457","DOI":"10.1016\/j.comcom.2012.04.012","volume":"35","author":"H Zhang","year":"2012","unstructured":"H. Zhang, G. Lu, M.T. Qassrawi, Y. Zhang, X. Yu, Feature selection for optimizing traffic classification. Comput. Commun. 35, 1457\u20131471 (2012)","journal-title":"Comput. Commun."},{"key":"2103_CR33","first-page":"1097","volume":"25","author":"A Krizhevsky","year":"2012","unstructured":"A. Krizhevsky, I. Sutskever, G.E. Hinton, Imagenet classification with deep convolutional neural networks. Adv. Neural. Inf. Process. Syst. 25, 1097\u20131105 (2012)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"2103_CR34","doi-asserted-by":"publisher","first-page":"3387","DOI":"10.1007\/s13042-019-00925-6","volume":"10","author":"Q Yan","year":"2019","unstructured":"Q. Yan, M. Wang, W. Huang, X. Luo, F.R. Yu, Automatically synthesizing dos attack traces using generative adversarial networks. Int. J. Mach. Learn. Cybern. 10, 3387\u20133396 (2019)","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"2103_CR35","doi-asserted-by":"crossref","unstructured":"P. Lin, K. Ye, C.-Z. Xu, Dynamic network anomaly detection system by using deep learning techniques. In: International Conference on Cloud Computing, pp. 161\u2013176 (2019). Springer","DOI":"10.1007\/978-3-030-23502-4_12"},{"key":"2103_CR36","doi-asserted-by":"crossref","unstructured":"Y. Zhang, X. Chen, D. Guo, M. Song, X. Wang, Pccn: Parallel cross convolutional neural network for abnormal network traffic flows detection in multi-class imbalanced network traffic flows. IEEE Access, pp. 1\u20131 (2019)","DOI":"10.1109\/ACCESS.2019.2933165"},{"key":"2103_CR37","doi-asserted-by":"publisher","first-page":"107049","DOI":"10.1016\/j.comnet.2019.107049","volume":"169","author":"Y Zhong","year":"2019","unstructured":"Y. Zhong, W. Chen, Z. Wang, Y. Chen, K. Li, Helad: A novel network anomaly detection model based on heterogeneous ensemble learning. Comput. Netw. 169, 107049 (2019)","journal-title":"Comput. Netw."},{"key":"2103_CR38","unstructured":"A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A.N. Gomez, \u0141. Kaiser, I. Polosukhin, Attention is all you need. In: Advances in Neural Information Processing Systems, pp. 5998\u20136008 (2017)"},{"key":"2103_CR39","unstructured":"K. Han, Y. Wang, H. Chen, X. Chen, D. Tao, A survey on visual transformer. arXiv preprint arXiv:2012.12556 (2020)"},{"key":"2103_CR40","first-page":"9","volume":"1","author":"A Radford","year":"2019","unstructured":"A. Radford, J. Wu, R. Child, D. Luan, D. Amodei, I. Sutskever et al., Language models are unsupervised multitask learners. OpenAI blog 1, 9 (2019)","journal-title":"OpenAI blog"},{"key":"2103_CR41","doi-asserted-by":"crossref","unstructured":"M. Kim, G. Kim, S.-W. Lee, J.-W. Ha, St-bert: Cross-modal language model pre-training for end-to-end spoken language understanding. In: ICASSP 2021-2021 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 7478\u20137482 (2021). IEEE","DOI":"10.1109\/ICASSP39728.2021.9414558"},{"key":"2103_CR42","doi-asserted-by":"crossref","unstructured":"Y. Chang, Z. Huang, Q. Shen, The same size dilated attention network for keypoint detection. In: International Conference on Artificial Neural Networks, pp. 471\u2013483 (2019). Springer","DOI":"10.1007\/978-3-030-30487-4_37"},{"key":"2103_CR43","unstructured":"J. Chung, C. Gulcehre, K. Cho, Y. Bengio, Empirical evaluation of gated recurrent neural networks on sequence modeling. arXiv preprint arXiv:1412.3555 (2014)"},{"key":"2103_CR44","doi-asserted-by":"crossref","unstructured":"W. Liang, J. Long, K.-C. Li, J. Xu, N. Ma, X. Lei, A fast defogging image recognition algorithm based on bilateral hybrid filtering. ACM transactions on multimedia computing, communications, and applications (TOMM) 17, 1\u201316 (2021)","DOI":"10.1145\/3391297"},{"key":"2103_CR45","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1080\/09540091.2020.1753175","volume":"33","author":"T Xiao","year":"2021","unstructured":"T. Xiao, D. Han, J. He, K.-C. Li, R.F. de Mello, Multi-keyword ranked search based on mapping set matching in cloud ciphertext storage system. Connect. Sci. 33, 95\u2013112 (2021)","journal-title":"Connect. Sci."},{"key":"2103_CR46","doi-asserted-by":"crossref","unstructured":"W. Liang, D. Zhang, X. Lei, M. Tang, K.-C. Li, A. Zomaya, Circuit copyright blockchain: Blockchain-based homomorphic encryption for ip circuit protection. IEEE Trans. Emerg. Top. Comput. (2020)","DOI":"10.1109\/TETC.2020.2993032"},{"key":"2103_CR47","doi-asserted-by":"crossref","unstructured":"M. Li, D. Han, X. Yin, H. Liu, D. Li: Design and implementation of an anomaly network traffic detection model integrating temporal and spatial features. Secur. Commun. Netw. 2021 (2021)","DOI":"10.1155\/2021\/7045823"},{"issue":"12","key":"2103_CR48","doi-asserted-by":"publisher","first-page":"15815","DOI":"10.1109\/TVT.2020.3036631","volume":"69","author":"M Cui","year":"2020","unstructured":"M. Cui, D. Han, J. Wang, K.-C. Li, C.-C. Chang, Arfv: an efficient shared data auditing scheme supporting revocation for fog-assisted vehicular ad-hoc networks. IEEE Trans. Veh. Technol. 69(12), 15815\u201315827 (2020)","journal-title":"IEEE Trans. Veh. Technol."}],"container-title":["EURASIP Journal on Wireless Communications and Networking"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13638-022-02103-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13638-022-02103-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13638-022-02103-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T05:07:19Z","timestamp":1650863239000},"score":1,"resource":{"primary":{"URL":"https:\/\/jwcn-eurasipjournals.springeropen.com\/articles\/10.1186\/s13638-022-02103-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,25]]},"references-count":48,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,12]]}},"alternative-id":["2103"],"URL":"https:\/\/doi.org\/10.1186\/s13638-022-02103-9","relation":{},"ISSN":["1687-1499"],"issn-type":[{"value":"1687-1499","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,25]]},"assertion":[{"value":"5 September 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 April 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"39"}}